GHSA-v3mr-gp7j-pw5w
Dashboard / Vulnerabilities / GHSA-v3mr-gp7j-pw5w
GHSA-v3mr-gp7j-pw5w
Summary: Possible SQL injection in tablelookupwizard Contao Extension
Details: ### Impact The currently selected widget values were not correctly sanitized before passing it to the database, leading to an SQL injection possibility. ### Patches The issue has been patched in `tablelookupwizard` version 3.3.5 and version 4.0.0. ### For more information If you have any questions or comments about this advisory: * Open an issue in https://github.com/terminal42/contao-tablelookupwizard * Email us at [[email protected]](mailto:[email protected])
References: https://github.com/terminal42/contao-tablelookupwizard/security/advisories/GHSA-v3mr-gp7j-pw5w, https://github.com/terminal42/contao-tablelookupwizard/commit/a5e723a28f110b7df8ffc4175cef9b061d3cc717, https://github.com/FriendsOfPHP/security-advisories/blob/master/terminal42/contao-tablelookupwizard/2022-02-04-1.yaml, https://github.com/terminal42/contao-tablelookupwizard
Affected packages
Package
Name: terminal42/contao-tablelookupwizard
Purl: pkg:composer/terminal42/contao-tablelookupwizard
Affected ranges
Type: ECOSYSTEM
Events:
